This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Baseline

7 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

We can reset the host file.

OTL Fix
Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :OTL
    
    PRC
    
    :Services
    
    :Reg
    
    :Files
    
    
    :Commands
    [EmptyFlash]
    [EmptyTemp]
    [RESETHOSTS] 
    [purity]
    [start explorer]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, it will reboot when it is done and produce a log
It's getting slower and slower to load the pages it does load

OTL logfile created on: 8/25/2010 8:00:05 PM - Run 5
OTL by OldTimer - Version 3.2.10.0 Folder = C:\Users\Amanda\Desktop
64bit- Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

4.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 64.00% Memory free
7.00 Gb Paging File | 6.00 Gb Available in Paging File | 81.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 684.87 Gb Total Space | 630.58 Gb Free Space | 92.07% Space Free | Partition Type: NTFS
Drive D: | 586.62 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: TANZEER
Current User Name: Amanda
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Include 64bit Scans
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Users\Amanda\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\AVG\AVG9\avgemc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files (x86)\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files (x86)\AVG\AVG9\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files (x86)\AVG\AVG9\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\Program Files (x86)\Acer\Registration\GregHSRW.exe (Acer Incorporated)
PRC - C:\Program Files (x86)\Acer\Hotkey Utility\HotkeyUtility.exe ()
PRC - C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe (NewTech Infosystems, Inc.)
PRC - C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe (NewTech Infosystems, Inc.)
PRC - C:\Windows\SysWOW64\Macromed\Flash\FlashUtil10c.exe (Adobe Systems, Inc.)
PRC - C:\Program Files\Acer\Acer Updater\UpdaterService.exe (Acer)


========== Modules (SafeList) ==========

MOD - C:\Users\Amanda\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Windows\SysWOW64\msscript.ocx (Microsoft Corporation)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_421189da2b7fabfc\comctl32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV:64bit: - (!SASCORE) – C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE File not found
SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV:64bit: - (Updater Service) – C:\Program Files\Acer\Acer Updater\UpdaterService.exe (Acer)
SRV:64bit: - (ForceWare Intelligent Application Manager (IAM)) – C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe ()
SRV:64bit: - (nSvcIp) – C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe ()
SRV - (avg9emc) – C:\Program Files (x86)\AVG\AVG9\avgemc.exe (AVG Technologies CZ, s.r.o.)
SRV - (avg9wd) – C:\Program Files (x86)\AVG\AVG9\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (Apple Mobile Device) – C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (AVG Security Toolbar Service) – C:\Program Files (x86)\AVG\AVG9\Toolbar\ToolbarBroker.exe ()
SRV - (clr_optimization_v4.0.30319_64) – C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (Greg_Service) – C:\Program Files (x86)\Acer\Registration\GregHSRW.exe (Acer Incorporated)
SRV - (Nero BackItUp Scheduler 4.0) – C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe (Nero AG)
SRV - (NTI IScheduleSvc) – C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe (NewTech Infosystems, Inc.)
SRV - (GameConsoleService) – C:\Program Files (x86)\Acer Games\Acer Game Console\GameConsoleService.exe (WildTangent, Inc.)


========== Driver Services (SafeList) ==========

DRV:64bit: - (AvgTdiA) – C:\Windows\SysNative\drivers\avgtdia.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (AvgLdx64) – C:\Windows\SysNative\drivers\avgldx64.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (AvgMfx64) – C:\Windows\SysNative\drivers\avgmfx64.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (USBAAPL64) – C:\Windows\SysNative\drivers\usbaapl64.sys (Apple, Inc.)
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (NVHDA) – C:\Windows\SysNative\drivers\nvhda64v.sys (NVIDIA Corporation)
DRV:64bit: - (Ntfs) – C:\Windows\SysNative\wbem\ntfs.mof ()
DRV:64bit: - (NVENETFD) – C:\Windows\SysNative\drivers\nvm62x64.sys (NVIDIA Corporation)
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (GEARAspiWDM) – C:\Windows\SysNative\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV:64bit: - (NTIDrvr) – C:\Windows\SysNative\drivers\NTIDrvr.sys (NewTech Infosystems, Inc.)
DRV:64bit: - (UBHelper) – C:\Windows\SysNative\drivers\UBHelper.sys (NewTech Infosystems Corporation)
DRV:64bit: - (pelmouse) – C:\Windows\SysNative\drivers\PELMOUSE.SYS (TPMX Electronics Ltd.)
DRV:64bit: - (pelusblf) – C:\Windows\SysNative\drivers\PELUSBlf.SYS (TPMX Electronics Ltd.)
DRV:64bit: - (NVNET) – C:\Windows\SysNative\drivers\nvmf6264.sys (NVIDIA Corporation)

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.acer.com/rdr.aspx?b=ACAW&a…78v115w4541t555
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://homepage.acer.com/rdr.aspx?b=ACAW&a…78v115w4541t555
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files (x86)\AVG\AVG9\Toolbar\IEToolbar.dll ()
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local



O1 HOSTS File: ([2010/08/17 21:06:16 | 000,393,152 | R— | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 127.0.0.1 1-2005-search.com
O1 - Hosts: 127.0.0.1 www.123fporn.info
O1 - Hosts: 13575 more lines…
O2:64bit: - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG9\avgssiea.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG9\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (AVG Security Toolbar BHO) - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files (x86)\AVG\AVG9\Toolbar\IEToolbar.dll ()
O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files (x86)\AVG\AVG9\Toolbar\IEToolbar.dll ()
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files (x86)\AVG\AVG9\Toolbar\IEToolbar.dll ()
O4:64bit: - HKLM..\Run: [Mouse Suite 98 Daemon] C:\Program Files\Rocketfish 2.4GHz Ergo Laser Mouse Driver\ICO.EXE (Primax Electronics Ltd.)
O4:64bit: - HKLM..\Run: [mwlDaemon] C:\Program Files (x86)\EgisTec\MyWinLocker 3\x86\mwlDaemon.exe File not found
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [Acer Assist Launcher] C:\Program Files (x86)\Acer\Acer Assist\launcher.exe ()
O4 - HKLM..\Run: [AVG9_TRAY] C:\Program Files (x86)\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [BackupManagerTray] C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe (NewTech Infosystems, Inc.)
O4 - HKLM..\Run: [Hotkey Utility] C:\Program Files (x86)\Acer\Hotkey Utility\HotkeyUtility.exe ()
O4 - HKCU..\Run: [msnmsgr] C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Windows\SysNative\nvLsp.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Windows\SysNative\nvLsp.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Windows\SysNative\nvLsp.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Windows\SysNative\nvLsp.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Windows\SysNative\nvLsp.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Windows\SysNative\nvLsp.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000017 - C:\Windows\SysNative\nvLsp.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000018 - C:\Windows\SysNative\nvLsp.dll File not found
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Windows\SysWOW64\nvLsp.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Windows\SysWOW64\nvLsp.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Windows\SysWOW64\nvLsp.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Windows\SysWOW64\nvLsp.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Windows\SysWOW64\nvLsp.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Windows\SysWOW64\nvLsp.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - C:\Windows\SysWOW64\nvLsp.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000018 - C:\Windows\SysWOW64\nvLsp.dll (NVIDIA)
O13 - gopher Prefix: missing
O13 - gopher Prefix: missing
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O18:64bit: - Protocol\Handler\avgsecuritytoolbar {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\http\oledb {E1D2BF40-A96B-11D1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\https\oledb {E1D2BF40-A96B-11D1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\ipp - No CLSID value found
O18:64bit: - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG9\avgppa.dll (AVG Technologies CZ, s.r.o.)
O18:64bit: - Protocol\Handler\msdaipp - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11D1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - Reg Error: Key error. File not found
O18 - Protocol\Handler\avgsecuritytoolbar {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - C:\Program Files (x86)\AVG\AVG9\Toolbar\IEToolbar.dll ()
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11D1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11D1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG9\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11D1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O20:64bit: - AppInit_DLLs: (avgrssta.dll) - C:\Windows\SysNative\avgrssta.dll (AVG Technologies CZ, s.r.o.)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysWow64\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/02/28 07:00:00 | 000,000,110 | R— | M] () - D:\AUTORUN.INF – [ CDFS ]
O33 - MountPoints2\{214887e9-58c6-11db-81af-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{214887e9-58c6-11db-81af-806e6f6e6963}\Shell\AutoRun\command - "" = D:\SETUP.EXE – [2006/02/28 07:00:00 | 001,314,816 | R— | M] (Microsoft Corporation)
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*


Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2010/08/24 20:29:14 | 000,000,000 | —D | C] – C:\_OTL
[2010/08/24 18:35:56 | 000,861,184 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\oleaut32.dll
[2010/08/24 18:31:44 | 000,050,688 | —- | C] (Atribune.org) – C:\Users\Amanda\Desktop\ATF-Cleaner.exe
[2010/08/21 14:27:38 | 000,000,000 | —D | C] – C:\MGtools
[2010/08/21 14:18:32 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\Windows\SysWow64\drivers\mbamswissarmy.sys
[2010/08/21 14:18:30 | 000,000,000 | —D | C] – C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2010/08/21 13:54:00 | 000,000,000 | —D | C] – C:\ProgramData\SUPERAntiSpyware.com
[2010/08/21 13:53:50 | 000,000,000 | —D | C] – C:\ProgramData\!SASCORE
[2010/08/21 10:15:08 | 000,575,488 | —- | C] (OldTimer Tools) – C:\Users\Amanda\Desktop\OTL.exe
[2010/08/21 10:04:55 | 000,000,000 | —D | C] – C:\Users\Amanda\AppData\Roaming\Template
[2010/08/21 09:39:02 | 000,000,000 | —D | C] – C:\Users\Amanda\AppData\Roaming\Yahoo!
[2010/08/21 09:39:00 | 000,000,000 | —D | C] – C:\Program Files (x86)\Yahoo!
[2010/08/20 23:59:23 | 000,000,000 | —D | C] – C:\Windows\Profiles
[2010/08/20 23:53:03 | 000,000,000 | -H-D | C] – C:\$AVG
[2010/08/19 21:45:31 | 000,000,000 | —D | C] – C:\ProgramData\Lavasoft
[2010/08/19 10:27:36 | 000,000,000 | —D | C] – C:\ProgramData\Alwil Software
[2010/08/19 10:27:36 | 000,000,000 | —D | C] – C:\Program Files\Alwil Software
[2010/08/17 23:15:02 | 000,000,000 | —D | C] – C:\ProgramData\TEMP
[2010/08/17 23:14:56 | 000,000,000 | —D | C] – C:\Program Files (x86)\SpywareBlaster
[2010/08/17 22:55:07 | 000,000,000 | —D | C] – C:\Users\Amanda\AppData\Roaming\Malwarebytes
[2010/08/17 22:54:25 | 000,024,664 | —- | C] (Malwarebytes Corporation) – C:\Windows\SysNative\drivers\mbam.sys
[2010/08/17 22:54:25 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2010/08/17 21:27:11 | 000,000,000 | —D | C] – C:\Program Files (x86)\Trend Micro
[2010/08/17 20:28:20 | 000,000,000 | —D | C] – C:\Users\Amanda\AppData\Roaming\Apple Computer
[2010/08/17 20:28:03 | 000,126,312 | —- | C] (GEAR Software Inc.) – C:\Windows\SysNative\GEARAspi64.dll
[2010/08/17 20:28:03 | 000,107,368 | —- | C] (GEAR Software Inc.) – C:\Windows\SysWow64\GEARAspi.dll
[2010/08/17 20:28:03 | 000,034,152 | —- | C] (GEAR Software Inc.) – C:\Windows\SysNative\drivers\GEARAspiWDM.sys
[2010/08/17 20:28:02 | 000,000,000 | —D | C] – C:\Windows\SysNative\DRVSTORE
[2010/08/17 20:27:54 | 000,000,000 | —D | C] – C:\Program Files\iPod
[2010/08/17 20:27:53 | 000,000,000 | —D | C] – C:\Program Files\iTunes
[2010/08/17 20:27:53 | 000,000,000 | —D | C] – C:\Program Files (x86)\iTunes
[2010/08/17 20:27:53 | 000,000,000 | —D | C] – C:\ProgramData\{93E26451-CD9A-43A5-A2FA-C42392EA4001}
[2010/08/17 20:25:47 | 000,000,000 | —D | C] – C:\Program Files (x86)\QuickTime
[2010/08/17 20:25:47 | 000,000,000 | —D | C] – C:\ProgramData\Apple Computer
[2010/08/17 20:25:39 | 000,000,000 | —D | C] – C:\Program Files (x86)\Apple Software Update
[2010/08/17 20:25:32 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Apple
[2010/08/17 20:25:15 | 000,000,000 | —D | C] – C:\Program Files\Bonjour
[2010/08/17 20:25:15 | 000,000,000 | —D | C] – C:\Program Files (x86)\Bonjour
[2010/08/17 20:25:09 | 000,000,000 | —D | C] – C:\ProgramData\Apple
[2010/08/17 20:25:09 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Apple
[2010/08/15 16:24:06 | 000,000,000 | —D | C] – C:\Users\Amanda\AppData\Local\ElevatedDiagnostics
[2010/08/12 03:00:37 | 000,000,000 | —D | C] – C:\3c4072fbf3210ae8298e6f3e29
[2010/08/11 21:04:56 | 005,507,968 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ntoskrnl.exe
[2010/08/11 21:04:56 | 003,955,080 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ntkrnlpa.exe
[2010/08/11 21:04:56 | 003,899,784 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ntoskrnl.exe
[2010/08/11 21:04:52 | 000,256,000 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iepeers.dll
[2010/08/11 21:04:52 | 000,185,856 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iepeers.dll
[2010/08/11 21:04:51 | 000,247,808 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieui.dll
[2010/08/11 21:04:51 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieui.dll
[2010/08/11 21:04:51 | 000,012,800 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msfeedssync.exe
[2010/08/11 21:04:51 | 000,012,288 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msfeedssync.exe
[2010/08/11 21:04:46 | 000,052,224 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\rtutils.dll
[2010/08/11 21:04:46 | 000,037,376 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\rtutils.dll
[2010/08/11 21:04:44 | 000,082,944 | —- | C] (Radius Inc.) – C:\Windows\SysWow64\iccvid.dll

========== Files - Modified Within 30 Days ==========

[2010/08/25 20:00:23 | 006,029,312 | -HS- | M] () – C:\Users\Amanda\NTUSER.DAT
[2010/08/25 19:53:40 | 000,009,920 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2010/08/25 19:53:40 | 000,009,920 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2010/08/25 19:53:28 | 000,726,316 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2010/08/25 19:53:28 | 000,623,940 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2010/08/25 19:53:28 | 000,106,316 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2010/08/25 19:46:31 | 000,000,894 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2010/08/25 19:46:27 | 000,000,006 | -H– | M] () – C:\Windows\tasks\SA.DAT
[2010/08/25 19:46:23 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2010/08/25 19:46:19 | 3018,756,096 | -HS- | M] () – C:\hiberfil.sys
[2010/08/25 19:45:39 | 001,133,283 | -H– | M] () – C:\Users\Amanda\AppData\Local\IconCache.db
[2010/08/25 19:45:04 | 000,000,898 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2010/08/24 13:29:04 | 000,050,688 | —- | M] (Atribune.org) – C:\Users\Amanda\Desktop\ATF-Cleaner.exe
[2010/08/21 20:25:42 | 000,001,212 | —- | M] () – C:\Users\Public\Desktop\World of Warcraft.lnk
[2010/08/21 14:31:06 | 000,174,034 | —- | M] () – C:\MGlogs.zip
[2010/08/21 14:18:34 | 000,001,013 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/08/21 10:15:08 | 000,575,488 | —- | M] (OldTimer Tools) – C:\Users\Amanda\Desktop\OTL.exe
[2010/08/21 10:04:44 | 000,000,000 | —- | M] () – C:\Users\Amanda\AppData\Roaming\wklnhst.dat
[2010/08/21 08:18:04 | 000,000,394 | —- | M] () – C:\Windows\tasks\Ad-Aware Update (Weekly).job
[2010/08/19 10:28:27 | 000,000,000 | —- | M] () – C:\Windows\SysWow64\config.nt
[2010/08/19 09:57:14 | 000,256,000 | —- | M] () – C:\Users\Amanda\Documents\New House Expenses.xls
[2010/08/17 23:14:59 | 000,001,007 | —- | M] () – C:\Users\Amanda\Desktop\SpywareBlaster.lnk
[2010/08/17 21:27:11 | 000,002,981 | —- | M] () – C:\Users\Amanda\Desktop\HiJackThis.lnk
[2010/08/17 21:06:16 | 000,393,152 | R— | M] () – C:\Windows\SysNative\drivers\etc\hosts
[2010/08/17 20:35:24 | 000,000,000 | -H– | M] () – C:\Windows\SysNative\drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
[2010/08/17 20:28:11 | 000,002,429 | —- | M] () – C:\Users\Public\Desktop\iTunes.lnk
[2010/08/17 20:25:50 | 000,001,849 | —- | M] () – C:\Users\Public\Desktop\QuickTime Player.lnk
[2010/08/12 03:19:49 | 000,341,248 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2010/08/09 22:39:56 | 063,176,281 | —- | M] () – C:\Windows\SysNative\drivers\Avg\incavi.avm
[2010/07/29 01:30:34 | 000,082,944 | —- | M] (Radius Inc.) – C:\Windows\SysWow64\iccvid.dll

========== Files Created - No Company Name ==========

[2010/08/21 14:27:40 | 000,174,034 | —- | C] () – C:\MGlogs.zip
[2010/08/21 14:18:34 | 000,001,013 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/08/21 10:04:44 | 000,000,000 | —- | C] () – C:\Users\Amanda\AppData\Roaming\wklnhst.dat
[2010/08/19 21:58:04 | 000,000,394 | —- | C] () – C:\Windows\tasks\Ad-Aware Update (Weekly).job
[2010/08/19 10:28:27 | 000,000,000 | —- | C] () – C:\Windows\SysWow64\config.nt
[2010/08/17 23:14:59 | 000,001,007 | —- | C] () – C:\Users\Amanda\Desktop\SpywareBlaster.lnk
[2010/08/17 21:27:11 | 000,002,981 | —- | C] () – C:\Users\Amanda\Desktop\HiJackThis.lnk
[2010/08/17 20:35:24 | 000,000,000 | -H– | C] () – C:\Windows\SysNative\drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
[2010/08/17 20:28:11 | 000,002,429 | —- | C] () – C:\Users\Public\Desktop\iTunes.lnk
[2010/08/17 20:25:50 | 000,001,849 | —- | C] () – C:\Users\Public\Desktop\QuickTime Player.lnk
[2010/08/15 16:19:03 | 000,015,698 | —- | C] () – C:\Users\Amanda\AppData\Local\MyWinLockerInstaller.txt-20100815.log
[2010/06/22 19:46:06 | 000,000,234 | —- | C] () – C:\Windows\WinInit.Ini
[2010/05/16 14:04:33 | 000,000,376 | —- | C] () – C:\Windows\ODBC.INI
[2009/07/13 18:42:10 | 000,064,000 | —- | C] () – C:\Windows\SysWow64\BWContextHandler.dll
[2009/07/13 16:03:59 | 000,364,544 | —- | C] () – C:\Windows\SysWow64\msjetoledb40.dll
[1999/01/22 13:46:56 | 000,065,536 | —- | C] () – C:\Windows\SysWow64\MSRTEDIT.DLL

========== LOP Check ==========

[2010/05/08 19:09:42 | 000,000,000 | —D | M] – C:\Users\Amanda\AppData\Roaming\Acer
[2010/05/08 19:09:41 | 000,000,000 | —D | M] – C:\Users\Amanda\AppData\Roaming\Leadertech
[2010/08/21 10:04:55 | 000,000,000 | —D | M] – C:\Users\Amanda\AppData\Roaming\Template
[2010/05/09 12:58:09 | 000,000,000 | —D | M] – C:\Users\Amanda\AppData\Roaming\WildTangent
[2010/08/21 08:18:04 | 000,000,394 | —- | M] () – C:\Windows\Tasks\Ad-Aware Update (Weekly).job
[2010/07/15 09:08:31 | 000,032,638 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2010/08/21 08:16:37 | 000,000,444 | —- | M] () – C:\aaw7boot.log
[2009/10/28 01:29:13 | 000,008,192 | RHS- | M] () – C:\BOOTSECT.BAK
[2009/10/07 11:24:27 | 000,003,411 | —- | M] () \E0Z0LP11.MD5 – C:\E0Z0LP11.MD5
[2010/08/25 19:46:19 | 3018,756,096 | -HS- | M] () – C:\hiberfil.sys
[2009/10/07 11:23:28 | 000,000,308 | —- | M] () – C:\LPCD.DAT
[2010/08/21 14:31:06 | 000,174,034 | —- | M] () – C:\MGlogs.zip
[2010/08/25 19:46:20 | 4025,012,224 | -HS- | M] () – C:\pagefile.sys
[2009/10/28 00:47:27 | 000,002,035 | —- | M] () – C:\RHDSetup.log

< %systemroot%\Fonts\*.com >
[2009/07/14 00:32:31 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/14 00:32:31 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/14 00:32:31 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/07/14 00:32:31 | 000,043,318 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2009/06/10 15:49:50 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2009/07/13 23:54:24 | 000,000,174 | -HS- | M] () – C:\Program Files (x86)\desktop.ini

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2010/05/08 19:52:51 | 000,000,221 | -HS- | M] () – C:\Users\Amanda\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >
[2010/08/24 13:29:04 | 000,050,688 | —- | M] (Atribune.org) – C:\Users\Amanda\Desktop\ATF-Cleaner.exe
[2010/08/21 10:15:08 | 000,575,488 | —- | M] (OldTimer Tools) – C:\Users\Amanda\Desktop\OTL.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >

< >

========== Alternate Data Streams ==========

@Alternate Data Stream - 118 bytes -> C:\ProgramData\TEMP:5C321E34
< End of report >
Lets try this again only with less things for OTL to do.
This shouldn't take more than a few minutes.

OTL Fix
Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :OTL
    
    :Commands
    [EmptyTemp]
    [RESETHOSTS] 
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, it will reboot when it is done and produce a log
All processes killed ========== OTL ========== ========== COMMANDS ========== [EMPTYTEMP] User: All Users User: Amanda ->Temp folder emptied: 186699 bytes ->Temporary Internet Files folder emptied: 36087661 bytes ->Flash cache emptied: 6272 bytes User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Public %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32 (64bit) .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 84369 bytes %systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 50132 bytes RecycleBin emptied: 67062 bytes Total Files Cleaned = 35.00 mb C:\Windows\System32\drivers\etc\Hosts moved successfully. HOSTS file reset successfully OTL by OldTimer - Version 3.2.10.0 log created on 08262010_192332 Files\Folders moved on Reboot… C:\Users\Amanda\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully. File\Folder C:\Users\Amanda\AppData\Local\Temp\~DF8E3846935EF26EA5.TMP not found! File\Folder C:\Users\Amanda\AppData\Local\Temp\~DFB3849DB9D240C2F8.TMP not found! File\Folder C:\Users\Amanda\AppData\Local\Temp\~DFC1BD016066D6278C.TMP not found! File\Folder C:\Users\Amanda\AppData\Local\Temp\~DFFE53821BF1773D67.TMP not found! Registry entries deleted on Reboot…
Please download Malwarebytes' Anti-Malware to your desktop.

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
    [external image: Posted Image]
  • When the scan is complete, click OK, then Show Results to view the results.
  • [external image: Posted Image]
  • Then click Remove Selected .
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.


Also please describe how your computer behaves at the moment.


Please don't attach the scans / logs, use "copy/paste".
your link will not load, but i already had malware bytes am running a scan now, but previous scans found nothing. Malwarebytes' Anti-Malware 1.46 www.malwarebytes.org Database version: 4487 Windows 6.1.7600 Internet Explorer 8.0.7600.16385 8/26/2010 8:09:32 PM mbam-log-2010-08-26 (20-09-32).txt Scan type: Quick scan Objects scanned: 130459 Time elapsed: 3 minute(s), 19 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected)
About 10 pm last night it suddenly started working I wasn't even doing anything. It may have been a problem with my provider, I don't know. Thank you for all your help and time. If it happens again I'll try to reset the router. Thank you.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI